Red Hat Security Advisory: Red Hat JBoss Web Server 3.1 Service Pack 8 security update
🔗 CVE IDs covered (4)
📋 Description
CVE-2019-0221 — tomcat: XSS in SSI printenv CVE-2019-12418 — tomcat: local privilege escalation CVE-2019-17563 — tomcat: Session fixation when using FORM authentication CVE-2020-1938 — tomcat: Apache Tomcat AJP File Read/Inclusion Vulnerability
🎯 Affected products1
- Red Hat JBoss Web Server 3.1
✅ Remediation
Before applying the update, back up your existing Red Hat JBoss Web Server installation (including all applications and configuration files). The References section of this erratum contains a download link (you must log in to download the update). Workaround: SSI is disabled in the default Tomcat configuration. The vulnerable printenv command is intended for debugging, and is recommended to not be enabled for a production website. Workaround: Disable JMX Remote if monitoring is only needed locally and there is no need to monitor Tomcat remotely. If JMX Remote is required and cannot be disabled, then use the built-in remote JMX facilities provided by the JVM. Please note that JMX Remote Lifecycle Listener is now deprecated and may be removed from both Tomcat 7 [1] and Tomcat 9 [2] after 2020-12-31. [1] https://tomcat.apache.org/tomcat-7.0-doc/config/listeners.html#Deprecated_Implementations [2] https://tomcat.apache.org/tomcat-9.0-doc/config/listeners.html#Deprecated_Implementations Workaround: Please refer to the Red Hat knowledgebase article: https://access.redhat.com/solutions/4851251
🔗 References (9)
- selfhttps://access.redhat.com/errata/RHSA-2020:0860
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://access.redhat.com/jbossnetwork/restricted/listSoftware.html?product=webserver&downloadType=securityPatches&version=3.1
- externalhttps://access.redhat.com/documentation/en-us/red_hat_jboss_web_server/3.1/html/3.1.0_release_notes/index
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1713275
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1785699
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1785711
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1806398
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2020/rhsa-2020_0860.json